- Distribution Method : Unknown
- MD5 : 60fb5f47a2df907fbf1d319d4c050175
- Major Detection Name : Trojan.RansomKD.12377708 (BitDefender), Ransom_FAKEGLOBE.ASUUH (Trend Micro)
- Encrypted File Pattern : .ocean
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Roaming\<Random>.exe
- Payment Instruction File : MESSAGE.html
- Major Characteristics :
- Offline Encryption
- Fake Globe / PSCrypt Ransomware series
- Disable system restore (vssadmin.exe Delete Shadows /All /Quiet)
List